77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Tasks of a data protection officer according to Art. 39 GDPR: list of duties with evidence structure
Data Protection & Privacy

Tasks of a data protection officer according to Art. 39 GDPR: list of duties with evidence structure

30 July 202612 min readBy Lena Vogt
CIVAC

Art. 39 GDPR lists five core tasks of the data protection officer. This guide breaks down each obligation into operational steps, describes the necessary evidence structure and shows how CIVAC bundles ordering, reporting lines and documentation into one workspace.

Art. Since May 25, 2018, Article 39 of the GDPR has defined the minimum tasks of each designated data protection officer and ties them directly to the accountability of the person responsible in accordance with Article 5 (2) of the GDPR. The wording lists five areas of responsibility: information and advice, monitoring compliance, advice in connection with data protection impact assessment, cooperation with the supervisory authority and function as a contact point for those affected. Anyone who cannot prove one of these obligations will immediately find themselves in need of explanation during an examination in accordance with Art. 58 GDPR. Since 2024, the supervisory authorities in Germany have been carrying out more independent checks, often using questionnaires with 30 to 60 detailed points.

This article breaks down each task into operational components, assigns it a form of evidence and describes how the duties can be carried out in parallel with day-to-day business without additional effort. The wording, systematics with Art. 37 and 38 GDPR, interfaces to Section 38 BDSG, risk orientation according to Art. 39 Paragraph 2 and the reporting line to management are discussed. CIVAC sees itself as a compliance platform and officer-as-a-service: you either receive a workspace in which your internal representative processes Art. 39 in a structured manner, or appoint an external data protection officer who takes over the duties and brings along the appointment document, reporting line and activity documentation. Both ways provide the same thing: verifiable evidence instead of loose activities.

Key Takeaways

  • Art. 39 Para. 1 GDPR names five core tasks of the DPO and makes them an auditable duty of the person responsible.
  • Each of the five tasks requires its own form of evidence: training register, audit ticket, DPIA accompanying protocol, correspondence with authorities and inquiry log.
  • Without a documented reporting line to the highest management level in accordance with Art. 38 Para. 3 GDPR, operational work loses its audit robustness.

Wording and system of Article 39 GDPR

Art. 39 Para. 1 GDPR formulates the list of obligations in five letters a to e and adds the risk orientation in Para. 2: The data protection officer takes due account of his tasks and takes into account the risk associated with the processing operations as well as the type, scope, circumstances and purposes of the processing. This risk orientation is not an add-on, but rather decides which processing operations are to be examined as a priority and which consultations need to be carried out in more depth. Anyone who treats all processing in the same way is not directly violating the norm, but is wasting testing capacity and, in cases of doubt, neglecting high risks, such as employee data in HR cloud systems or health data in company pension plans.

Systematically, Art. 39 belongs to the triad of agent regulations: Art. 37 regulates the obligation to name and its thresholds, Art. 38 the position and independence, Art. 39 the list of tasks. Anyone who reads Article 39 in isolation misses the connection with Section 38 BDSG, which adds for non-public bodies in Germany: A DPO must be appointed as soon as at least 20 people are generally constantly involved in the automated processing of personal data. There are also special cases such as extensive processing of special data categories in accordance with Art. 9 GDPR or the regular and systematic monitoring of those affected on a large scale. According to Article 37 Paragraph 1 Letter a of the GDPR, public bodies are also required to be named regardless of the number of employees. If you want to check the designation threshold, you can find details under the external data protection officer and in the CIVAC FAQ. The tasks from Art. 39 only take effect when the order, appointment certificate and reporting line are clearly documented. The appointment certificate, signed, filed, verifiable. Without these three pieces of evidence, the examiner is already frowning in Questionnaire No. 1. With them, the audit begins on a solid basis, which usually opens with questions about appointments, areas of responsibility and reporting line before substantive topics come to the table.

Information and advice (Art. 39 para. 1 lit. a)

The first task obliges the DPO to inform and advise the controller, the processor and the employees about their obligations under the GDPR and other data protection regulations. In practice, this obligation is broken down into four components: regular data protection training for all employees with contact with data processing, advising on specific occasions for new processing operations, written statements on contracts in accordance with Art. 28 GDPR and update briefings in accordance with each guideline of the European Data Protection Board or relevant case law of the ECJ and BGH. Anyone who manages these four modules separately will quickly reach the limits of their own overview.

The form of proof is a training and advice register with date, recipient group, content, source reference and learning control. Anyone who only provides information orally cannot later prove that employees have been informed about the 72-hour reporting requirement according to Art. 33 GDPR or the information obligations according to Art. 13 GDPR. We recommend annual mandatory training with proof of participation as well as role-specific in-depth training for HR, IT, sales and marketing, supplemented by onboarding modules for new employees within the first 30 days. For special occasions, such as the introduction of a new CRM or a Microsoft 365 migration, an event-related advisory note is mandatory: What risk was discussed, what measure was recommended, what decision was made? In the CIVAC workspace, training templates, participation lists and consultation protocols are stored as linked data sets; Search queries like all Microsoft 365 consultations in Q3 deliver hits in seconds instead of after hours of looking through folders. Order processing contracts in accordance with Art. 28 GDPR are also checked against an 18-point checklist and filed with the date, examiner and findings. Others run compliance like a filing cabinet. We run it like software. This means that every single consultation process can be shown to the supervisor in seconds.

Monitoring compliance (Art. 39 para. 1 lit. b)

The monitoring obligation is the most extensive task and, according to the wording, includes the monitoring of compliance with the GDPR, other Union or Member State data protection legislation and the controller or processor's strategies for the protection of personal data, including the allocation of responsibilities, staff awareness and training and related reviews. That is in plain language: audits. And not once, but in a rolling cycle, the frequency of which is derived from the risk of the respective processing. Anyone who equates monitoring with annual sampling clearly underestimates the continuous observation and reporting obligation under Article 39 Paragraph 1 Letter b.

Specifically, this means at least five recurring audit steps: maintenance and spot checks of the list of processing activities in accordance with Art. 30 GDPR, review of order processing contracts in accordance with Art. 28 GDPR, control of technical and organisational measures in accordance with Art. 32 GDPR, ability to respond to the rights of those affected in accordance with Art. 15 to 22 GDPR and examination of third country transfers in accordance with Art. 44 ff. In addition, there are event-related checks for every organisational change, for every new tool and for every unusual incident. Each test generates a report with the date, scope of the test, findings, risk classification, recommended measures, person responsible and resubmission date. CIVAC supplies 490 ready-to-use audit templates that structure these audits according to Art. 39 and import the findings directly into the central register of measures. Finding severity levels follow a four-stage scale from observed to critical; each measure is given a deadline and a person responsible. If you want to know how monitoring is interlinked with ISO/IEC 27001:2022 controls, you can find the bridge at ISO 27001:2022 Transition. The 93 controls of the standard provide the technical foundation that operationalizes Art. 32 GDPR and thus supports the monitoring obligation under Art. 39. The auditor calls, the evidence is ready. Just a few clicks show the last audit date, findings, status of measures and responsibility, supplemented by the version history of changed documents.

Advice on data protection impact assessment (Art. 39 para. 1 lit. c)

The DPO provides advice on request in connection with the data protection impact assessment and monitors its implementation in accordance with Art. 35 GDPR. This obligation is formulated narrowly: The DPO does not carry out the DPIA himself, because that is the responsibility of the person responsible. He accompanies, checks and comments. It is precisely this support that must be documented, otherwise it cannot be proven later that the DSB was involved. The separation ensures independence according to Art. 38 Para. 3 GDPR and avoids conflicts of interest according to Art. 38 Para. 6 GDPR, in which the DPO would essentially audit itself.

A complete DPIA file contains nine components: systematic processing description, necessity and proportionality test, risk assessment for the rights and freedoms of the data subjects, remedial measures, statement of the DPO according to Art. 35 Para. 2 GDPR, if necessary consultation with the supervisory authority in accordance with Art. 36 GDPR, approval status, review date and version history. Typical processing operations subject to DPIA include biometric access controls, AI-supported applicant selection, comprehensive profiling, scoring procedures and video surveillance of publicly accessible areas; The positive list of the respective supervisory authority is mandatory reading and differs between the federal states. The DSK short papers No. 5 and No. 18 as well as the EDPB guideline WP248 rev.01 provide the methodological framework. In the CIVAC workspace, the DPIA is created as a workflow with mandatory fields; A DPIA threshold test will decide before starting whether a full impact assessment is required. You can licence the workspace so that your internal DPO manages the DPIA in a structured manner, or you can appoint our representatives to provide DPIA support and statements, including the review cycle. Licence the workspace for your internal representatives, or have our representatives order it. Both methods fully comply with Article 39 Paragraph 1 Letter c and provide a file that can be handed over to the supervisory authority in the event of a consultation without rework.

Cooperation with the supervisory authority (Art. 39 para. 1 lit. d)

The fourth task requires the DPO to cooperate with the supervisory authority. This includes active duties and reactive duties. Active obligations include, for example, prior consultation in accordance with Art. 36 GDPR in the event of a high residual risk and the transmission of reports in accordance with Art. 33 GDPR in the event of data protection violations, provided that this has been transferred to the DPO in the organisation. Reactive obligations include answering official inquiries, accompanying on-site inspections in accordance with Art. 58 Para. 1 lit. f GDPR and providing requested documents within the set deadline, which in practice is often only 14 days.

The 72-hour deadline from Art. 33 GDPR is the hard pace setter here. Deadline begins as soon as we become aware of it. Anyone who does not report within this deadline risks fines in accordance with Article 83 (4) (a) GDPR of up to 10 million euros or 2% of global annual turnover. In addition, there are follow-up requirements pursuant to Article 58 (2) GDPR, which in practice can be more sensitive than the fine itself because they interrupt ongoing business processes. A reporting path is stored in the CIVAC workspace, which records the violation, affected data categories, number of affected people, possible consequences and measures taken within minutes and automatically generates a template and escalation path to the responsible supervisory authority. For companies subject to NIS 2, the 24/72 reporting path runs in parallel with early warning to the BSI and follow-up reporting after 72 hours. Correspondence with supervisors is stored entirely in the workspace; each request receives a ticket with a deadline, person responsible and status history. On-site examinations run via a separate examination module with a preparation checklist, handover protocol and follow-up appointment. Audit-proof, documented, Art. 33-firm. For every official request, management receives a concise assessment of the situation without delay, so that internal decisions are synchronized with external communication.

Contact point for those affected (Art. 39 para. 1 lit. e)

The DSB is the contact point for those affected for all questions relating to the processing of their personal data and the exercise of their rights under the GDPR. In practice, this means: a separate communication channel, a published contact address in accordance with Art. 37 Para. 7 GDPR and a procedure that processes requests from those affected within the one-month period specified in Art. 12 Para. 3 GDPR. In complex cases, the processing time may be extended by another two months; However, this must be justified and communicated to the person affected within the first month, otherwise the extension will be ineffective.

The processing of the rights of those affected is a separate process with clear input channels, identity verification, research, draft answer, four-eye approval and filing. Frequent requests include information according to Art. 15, correction according to Art. 16, deletion according to Art. 17, restriction according to Art. 18 and data portability according to Art. 20 GDPR. In addition, there are contradictions according to Art. 21 GDPR, which make up the majority of receipts in sales-related organisations. Without a ticket system and deadline controlling, every organisation loses overview; 50 inquiries per year already blow up an inbox. In the CIVAC workspace, inquiries from those affected are processed via a separate module with confirmation of receipt, deadline traffic light and response templates; Responses are documented with date, processor, approver and shipping channel. Identity verification is risk-based: an in-depth check is carried out for requests for information about sensitive data, and the confirmation link procedure is used for standard requests. If you want to check what the contact point function looks like in practice, you can find an overview of the roles on offer at CIVAC roles. The appointment as an external DPO always includes the contact point function, including German-speaking availability and EU data residency in the workspace. Inquiries from agency relationships and from group structures are routed via predefined role profiles so that no inquiry is leaked between group companies.

Risk orientation according to Art. 39 Para. 2 GDPR

Art. 39 Para. 2 GDPR states: When carrying out his tasks, the data protection officer shall take due account of the risk associated with the processing operations, taking into account the nature, scope, circumstances and purposes of the processing. This risk orientation requires the DSB to prioritise task planning instead of linear processing. It is the GDPR's answer to the simple fact that agent capacity is finite and not every processing can tolerate or requires the same level of scrutiny.

Operationally, this means: The DPO keeps a risk register in which all processing is classified according to potential for damage and probability of occurrence. High-risk processing is audited quarterly, medium-risk processing annually, low-risk processing every two years. This prioritization must be clearly documented, otherwise it could be interpreted as arbitrary. The risk classification typically follows four dimensions: data category according to Articles 9 and 10 GDPR, group of people affected including vulnerable groups such as minors or employees, scope of processing and technologies used such as profiling, AI or cloud services outside the EU. Anyone who only cites GDPR texts without showing this prioritization will be noticed during the first supervisory focus check because the official questionnaires explicitly ask about the risk approach. In the CIVAC workspace, the risk register combines processing activity, DPIA status, last audit finding and next review date in one view. ISO/IEC 27001:2022 with its 93 controls provides the technical and organisational foundation that supports the risk orientation of Art. 39 and specifies Art. 32 GDPR. Any change in risk, for example due to the introduction of new software or a new data stream to a third country, triggers an automatic review task for the DPO. This keeps the risk orientation alive instead of updating it once a year.

Reporting line, position and evidence in accordance with Art. 38 GDPR

The tasks from Art. 39 only take effect if the position of the DPO in accordance with Art. 38 GDPR is complied with. Art. 38 Para. 3 GDPR requires: The person responsible ensures that the DPO does not receive any instructions regarding the exercise of his or her tasks. He must not be dismissed or disadvantaged because he fulfils his duties. He reports directly to the highest management level. These three sentences are the foundation; Without it, all activities under Article 39 are vulnerable because the four-eye principle between the person responsible and the person responsible is missing.

This reporting line is more than an organisational chart box. It needs a documented format: regular annual reports, event-related escalations and a clear escalation procedure. The annual report typically contains ten components: status of processing activities, audits carried out, risks identified, data protection violations dealt with, data subject requests processed, training carried out, statements on DPIA, correspondence with the supervisory authority, open measures and recommendations to management. Without this report, the key piece of evidence that proves compliance with Article 39 is missing. CIVAC provides a report template as a workspace module; it is filled automatically from the data records maintained there; the DSB only adds assessments and recommendations. The report is signed and handed over to the management and stored as a version in the workspace. Event-related escalations, such as a high-risk data breach, are handled via a separate 24-hour path to management and the compliance function. This means that Article 39 does not create a collection of loose activities, but rather a verifiable line from task to evidence to report to decision. The supervisory authority immediately recognises whether the management was actually involved or whether the DPO was left alone, which according to ECJ case law is considered an organisational violation of Article 38.

Make an order out of Article 39: Workspace or Officer-as-a-Service

Art. 39 GDPR is not a list that you tick off once. The five tasks run in parallel, constantly and require proof. Anyone who runs it without a platform will eventually lose track of training statuses, audit cycles, DPIA progress, government deadlines and inquiries from those affected. CIVAC sees itself as the platform that translates these obligations into continuous operation. Compliance platform and officer-as-a-service in one environment, with EU data residency, ISO/IEC 27001:2022 compliant processes and documented reporting line to management. 25 representative roles are live, the DPO is one of them and is seamlessly interlinked with ISB, compliance officer and whistleblower protection.

You have two options: Licence the workspace for your internal representatives, then your DPO works with 490 audit templates, training register, DPIA module, reporting path and report template in a single environment. Or have our representatives appointed, then we will take over the order, appointment certificate, reporting line and the operational fulfilment of all five tasks in accordance with Art. 39 GDPR, with an SLA of two working days instead of the industry-standard two to six weeks for feedback. Both ways deliver the same result: appointment certificate, signed, filed, verifiable. We build the reporting line to fit your organisational structure, integrate existing tools via clearly defined interfaces and avoid double maintenance between DPO, IT security and compliance function. An initial structural discussion takes 45 minutes to clarify which path suits your organisation size, industry, international positioning and risk situation. Write to info@civac.de or use the contact form on civac.de. You will receive a concrete recommendation with an estimate of the effort and a draft appointment certificate within two working days. We then hand over an onboarding plan with milestones that makes the fulfilment of all five tasks from Art. 39 verifiable within 30 days. Turn reading into an assignment.

FAQ

Which five tasks does Article 39 Para. 1 GDPR specifically list?

Art. 39 Para. 1 GDPR mentions information and advice, monitoring of compliance, advice on data protection impact assessment, cooperation with the supervisory authority and the function as a contact point for those affected. Each of these tasks requires evidence and must be documented in a verifiable format so that the accountability obligation in accordance with Art. 5 Para. 2 GDPR can still be met.

Does the DPO have to carry out the data protection impact assessment himself in accordance with Art. 35 GDPR?

No. According to Art. 39 Para. 1 lit. c GDPR, the DPO advises and monitors the DPIA; it is carried out by the person responsible. The opinion of the DSB in accordance with Article 35 Para. 2 GDPR is part of the DPIA file. The separation ensures independence in accordance with Art. 38 Para. 3 GDPR and avoids a conflict of interest within the meaning of Art. 38 Para. 6 GDPR.

How does the DSB prove compliance with the list of obligations under Article 39 GDPR?

Via an activity register with training lists, audit reports, DPIA statements, reporting processes in accordance with Art. 33 GDPR and processing protocols on the rights of those affected. The annual report to the management bundles this evidence and makes the fulfilment of all five tasks verifiable and verifiable to the management and the supervisory authority. Without this bundled piece of evidence, compliance with Article 39 remains difficult for external auditors to reconstruct, even if all individual activities have taken place.

What are the consequences if tasks under Art. 39 GDPR are not fulfilled?

Violations of the DSB obligations are sanctioned under Article 83 (4) (a) GDPR, i.e. up to 10 million euros or 2% of global annual turnover. In addition, there are orders according to Art. 58 GDPR, reputational damage and personal liability risks for management according to Section 130 OWiG in the event of a lack of supervision over the DPO. In practice, accompanying requirements, such as an external data protection audit lasting twelve months, often cost more than the fine itself.

Does Art. 39 GDPR also apply to the external data protection officer?

Yes. Art. 37 Para. 6 GDPR makes it clear that the DPO can be an employee or an external service provider. The list of tasks in Article 39 applies identically in both cases. When ordering externally, the scope of services is fixed in a contract that fully reflects the tasks listed in Article 39 and anchors the reporting line to the management.

How long does it take to set up the Art. 39 structures with CIVAC?

The appointment of an external data protection officer is completed within two working days, including the appointment certificate, reporting line and workspace access. For internal representatives, the licensed workspace is also ready for use within two working days. Training registers, audit templates and reporting paths are preconfigured and only need to be adapted to your organisational structure. A migration path from existing file structures is defined during onboarding with clear responsibilities and milestones.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles